Provision record
TransUnion · TransUnion Privacy Policy [SPA-QUARANTINE: needs human capture] · View original document ↗

Personal Information Collection Scope

High severity Low confidence Inferredfromcontext Unique · 0 of 352 platforms
Get alerted the next time TransUnion changes these terms. Follow TransUnion →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for TransUnion Monitor emails you the same day this changes. The archive stays free.
Follow TransUnion →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy discloses that TransUnion collects personal information including identifiers, credit and financial data, demographic information, device and browsing data, and other categories across its consumer and commercial product lines. The specific categories are referenced under the 'Personal information we collect' section linked in the document navigation.

This analysis describes what TransUnion's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the foundational scope of TransUnion's data collection across both FCRA-regulated credit file functions and non-FCRA commercial analytics products, affecting the range of data subject rights and regulatory obligations that apply to different data categories.

Interpretive note: The full text of the 'Personal information we collect' section was not provided in the document excerpt; specific data categories and collection mechanisms cannot be confirmed from the navigation links alone.

Consumer impact (what this means for users)

The agreement authorizes collection of multiple categories of personal information, with the specific rights and protections available to consumers depending on whether the data is processed under FCRA as consumer report information or under non-FCRA commercial data frameworks.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Navigate to TransUnion's Consumer Support Services page and submit a data access or deletion request. Select the applicable request type and provide identity verification as prompted.

Cross-platform context

See how other platforms handle Personal Information Collection Scope and similar clauses.

Compare across platforms →

Monitoring

TransUnion has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow TransUnion → Or create a free account →
ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: The scope of personal information collected engages the FCRA (enforced by the CFPB and FTC) for credit and consumer report data, the CCPA/CPRA for California residents (enforced by the California Privacy Protection Agency), and GDPR for EU/EEA data subjects. The distinction between FCRA-covered data and non-FCRA commercial data is material because FCRA imposes permissible purpose restrictions, accuracy obligations, and dispute rights that do not apply to all data categories TransUnion processes. (2) GOVERNANCE EXPOSURE: High. TransUnion's collection of credit, financial, and identity data at scale across both regulated and commercial product lines creates layered compliance obligations. The risk of data category misclassification (treating FCRA-covered data as non-FCRA commercial data) is a documented regulatory concern for consumer reporting agencies. (3) JURISDICTION FLAGS: California residents have CCPA/CPRA rights including the right to know specific categories collected, right to deletion with FCRA-sourced exceptions, and right to opt out of sale or sharing. EU/EEA residents have GDPR Article 13/14 disclosure rights and rights to erasure subject to legal basis exceptions. FCRA dispute rights apply to all US consumers regardless of state. (4) CONTRACT AND VENDOR IMPLICATIONS: Organizations receiving TransUnion data as a vendor service should ensure data processing agreements specify the categories of data supplied, permissible uses, and whether the data constitutes consumer report information under FCRA, triggering downstream user certification and adverse action obligations. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should maintain a data inventory mapping each TransUnion product to the specific personal information categories collected and the applicable regulatory framework (FCRA vs. non-FCRA), to support accurate privacy notice disclosures and rights response workflows.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Applicable agencies

  • CFPB
    The CFPB enforces the FCRA with respect to consumer reporting agency data collection, accuracy, and permissible purpose obligations applicable to TransUnion's credit file data.
    File a complaint →
  • FTC
    The FTC has enforcement authority over TransUnion as a consumer reporting agency under FCRA and over data broker and privacy practices under the FTC Act.
    File a complaint →

Provision details

Document information
Document
TransUnion Privacy Policy [SPA-QUARANTINE: needs human capture]
Entity
TransUnion
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
July 9, 2026
Record ID
CA-P-016340
Document ID
CA-D-00593
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
0a4b327af10485321704d9a0d63c118970cc7edd3541cd157e28f1d3dea8ea56
Analysis generated
May 8, 2026 07:44 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: TransUnion
Document: TransUnion Privacy Policy [SPA-QUARANTINE: needs human capture]
Record ID: CA-P-016340
Captured: 2026-05-08 07:44:52 UTC
SHA-256: 0a4b327af1048532…
URL: https://conductatlas.com/platform/transunion/transunion-privacy-policy-spa-quarantine-needs-human-capture/provision/CA-P-016340/personal-information-collection-scope/
Accessed: July 26, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does TransUnion's Personal Information Collection Scope clause do?

This provision establishes the foundational scope of TransUnion's data collection across both FCRA-regulated credit file functions and non-FCRA commercial analytics products, affecting the range of data subject rights and regulatory obligations that apply to different data categories.

How does this clause affect you?

The agreement authorizes collection of multiple categories of personal information, with the specific rights and protections available to consumers depending on whether the data is processed under FCRA as consumer report information or under non-FCRA commercial data frameworks.

Is ConductAtlas affiliated with TransUnion?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by TransUnion.